search_family
Pack: malwarebazaar · Connect: https://pipeworx.io/mcp (see Connect below for a single-pack URL)
No MCP client? Call it directly: GET https://gateway.pipeworx.io/v1/tools/search_family for the schema, then POST the same URL with its arguments for the data.
Look up malware samples in MalwareBazaar (the abuse.ch sample corpus) attributed to one malware family or signature name, for example “Cobalt Strike” or “AgentTesla”. Returns the matching samples with sha256/md5 hashes, file type, file name, first and last seen dates, tags, and intel sources. Answers which samples of a named malware family have been submitted and how recently.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
family | string | yes | Family name (signature) |
limit | number | no | Max results (default 100) |
Example call
Arguments
{
"family": "Emotet"
}
curl
curl -X POST https://gateway.pipeworx.io/malwarebazaar/mcp \
-H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_family","arguments":{"family":"Emotet"}}}'
TypeScript (@pipeworx/sdk)
import { Pipeworx } from '@pipeworx/sdk';
const pipeworx = new Pipeworx();
const result = await pipeworx.call('search_family', {
"family": "Emotet"
});
More examples
{
"family": "Cobalt Strike",
"limit": 25
}
Response shape
Always returns: query, status, count, samples
| Field | Type | Description |
|---|---|---|
query | string | Query type used (get_siginfo) |
status | string | null | Query status (ok, no_results, or null) |
count | number | Number of samples returned |
samples | array | Array of samples from malware family |
Full JSON Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Query type used (get_siginfo)"
},
"status": {
"type": [
"string",
"null"
],
"description": "Query status (ok, no_results, or null)",
"enum": [
"ok",
"no_results",
null
]
},
"count": {
"type": "number",
"description": "Number of samples returned"
},
"samples": {
"type": "array",
"description": "Array of samples from malware family",
"items": {
"type": "object"
}
}
},
"required": [
"query",
"status",
"count",
"samples"
]
}
Connect
Add this to your MCP client config — every tool in the catalog, including this one — or use one-click install buttons:
{
"mcpServers": {
"pipeworx": {
"url": "https://pipeworx.io/mcp"
}
}
}
Connect to just the malwarebazaar pack
{
"mcpServers": {
"malwarebazaar": {
"url": "https://gateway.pipeworx.io/malwarebazaar/mcp"
}
}
}
See Getting Started for client-specific install steps.